56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-37899 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the | 1.0% | — |
| CVE-2025-37885 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route isn't postable Restore an IRTE back to host control (remapped or posted MSI mode) if the *new* GSI route prevents posting the IRQ directly | 0.3% | — |
| CVE-2025-37849 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCP | 0.3% | — |
| CVE-2025-37790 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: mctp: Set SOCK_RCU_FREE Bind lookup runs under RCU, so ensure that a socket doesn't go away in the middle of a lookup. | 0.3% | — |
| CVE-2025-37777 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __smb2_lease_break_noti() Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed | 0.3% | — |
| CVE-2025-37776 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use re | 0.3% | — |
| CVE-2025-36633 | HIGH 8.8 | tenable nessus_agent In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation. | 0.2% | — |
| CVE-2025-3619 | HIGH 8.8 | google chrome Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 0.5% | — |
| CVE-2025-36049 | HIGH 8.8 | ibm webmethods_integration IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. | 0.6% | — |
| CVE-2025-33073 | HIGH 8.8 | microsoft windows_10_1507 Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | 80.4% | |
| CVE-2025-33066 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-33064 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-33053 | HIGH 8.8 | microsoft windows_10_1507 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | 85.3% | |
| CVE-2025-30473 | HIGH 8.8 | apache airflow_common_sql_provider Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI | 0.9% | — |
| CVE-2025-29967 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-29966 | HIGH 8.8 | microsoft remote_desktop Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2025-29964 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29963 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29962 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 14.3% | — |
| CVE-2025-29840 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29794 | HIGH 8.8 | microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 4.9% | — |
| CVE-2025-27818 | HIGH 8.8 | apache kafka A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and | 0.9% | — |
| CVE-2025-27740 | HIGH 8.8 | microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. | 3.3% | — |
| CVE-2025-27696 | HIGH 8.8 | apache superset Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version | 1.2% | — |
| CVE-2025-27481 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.2% | — |